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It is crucial for public users and service providers to stay abreast of the 
progress and trends on data exfiltration in computer security system. In 
cryptosystem, it is unnoticeable for computer and mobile users to realize that 
inaudible sound used to transmit signals carrying pervasive sensitive data 
was in the low frequency ultrasonic range. Acoustic attacks on ultrasonic 
signal emanated by electronic devices have long been investigated among 
researchers. This paper is an exploration on the practicality of ultrasonic data 
exfiltration between computers in term of computer security system. It will 
discuss some work done by previous researchers in general, based on 
scientific, technological, and security perspectives. There will be inclusions 
of practical applications already in existence as well as future studies in 
related fields. 
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1. INTRODUCTION 

We live in the era where security is the main concern of protecting private information which is 
controlled via computer system. While the breach of such system has been shown to be feasible throughout 
the decades, the exfiltration of encrypted data for highly secured network computers [1]—[4] and mobile 
device [5]—[9] users are still considered a challenging task. A lot of efforts have been done in protecting this 
information but there are still many concerns for the security systems in which the orientation is visible and 
easily accessed. The focus nowadays is on the sound produced by computer peripherals such as keyboards 
[10], [11] and printers [12]. Technically this method of attack dates to the time of FFT-based hardware being 
easy enough to perform the tasks. Other conventional leakages can be power, electromagnetic radiation, 
optical and light emanation [13]-[15]. 

The development of ultrasonic data exfiltration in the context of an information security brings the 
possibility growth of data transmission via sound beyond the human hearing level. It is well known that 
sound can be used to transmit data as this can be seen in many old technologies especially for mobile system 
[6], [16]. This could provide the process of transmitting overhead data without the use of radio signals or 
physical connections or retrieving data virtually undetected for hacking, control, or other malicious activity. 


2. EVOLUTION OF ULTRASONIC IN TELECOMMUNICATION 

Wireless connectivity is crucial nowadays. One critical and urgent issue is the availability of 
wireless technology. Mobile devices like laptops, mobile phones and tablets, they communicate with echo 
what are known as radio waves. Useful radio waves are limited, expensive, strictly regulated and shortage of 
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suitable frequencies to be used. The unwanted wireless signals will significantly degrade desired signals and 
reduce system performance [17]. These impacts have led to the application of other alternative signals which 
is sound. Sound is a mechanical vibration or pressure wave that can be transmitted through a medium such as 
air, water or solid materials. Meanwhile ultrasound is a type of sound with a pitch or frequency above limit of 
human hearing (approximately more than 20kHz). It will not be able to hear without the help of a proper 
detector. The use of ultrasound becomes more attractive as if data signals were transmitted using audible 
sound the environment would be too noisy to be heard. 


2.1. The History 

The discoveries of ultrasonic frequency have been studied for many different reasons for hundreds 
of years. The first discovery started in 1794 when physiologist Lazzaro was the first to study the echolocation 
among bats. In 1877, Jacques and Pierre discovered the piezoelectric effect which was used in the transducers 
design for ultrasonic waves in air and water [18]. The successful application of piezoelectricity in the 
generation and detection of ultrasound waves in deep seawater was followed by further development as 
described in [18]-[20]. The first technological application of ultrasound dates back in 1916 which was 
inspired by the sinking of Titanic ship earlier before when Paul Langevin was trying to detect submarines 
using sound navigation and ranging technology also known as SONAR [21], [22]. Today, the development of 
ultrasound technology is used in many areas of life, especially in telecommunication [23], [24], heavy 
industry [25]-[27] and biomedical imaging [28], [29]. The frequency range of ultrasonic is very wide and 
depends on their use, ranging from 20 kHz in industrial devices up to 10 MHz in medical diagnostics and 
therapy. 


2.2. Ultrasonic in Modern Computer System 

The concept of transferring data over inaudible sound signal within high frequency range or simply 
known as ultrasonic data transmission cover a wide range of practical uses. A common way to send digital 
data using ultrasound is simply turning on and off the transmitter. When the receiving sensor detects the 
corresponding changes of sound pressure, this information can be converted back into an electrical signal and 
translated back to the original data. Digital data can be represented by a series of ultrasound bursts travelling 
as pressure waves through air. The sound signal that able to carry sensitive data imposed many opportunities 
and threats [30]. Transmitting anything in a low frequency range of ultrasonic can be considered exposing the 
data publicly but is hidden by anyone not looking for it. Nowadays most modern computers such as laptops 
and mobile phones have built in microphones and speakers. This means that in the absence of network cables 
and wireless signal, those built in devices can be utilized to control those systems maliciously. 

For computer system, among the earliest technology that become great interest among computer 
engineers for data transmission over sound is audio watermarking. The concept of watermarking or hiding 
data in sound signal has started to receive interest among professionals since year 1996 [31]. The fact that the 
limitation of the old concept can only transmit about one character per second, more development has been 
done via techniques using ultrasonic signals which can transmit information at higher speeds [32]-[34]. 
Ultrasonic data transmission in short range also known as near-sound data transfer (NSDT) enables secure 
transactions by creating an electronic signature using a one-time password through inaudible audio signal of 
a mobile device. This technology is primarily used for mobile banking can be very delicate as range of 
measurement can be affected by air flow, temperature changes, humidity or environmental signal [35]. 
Smarter design scheme need to be developed to deliver stealthy communication utilizing ultrasonic frequency 
range. 

For long distance tracking, multiple ultrasonic sensors are adopted to realize exactly locating motion 
objects with sophisticated scheme measuring their motion orientation so that their 2D coordinates should be 
located and positioned [36]. Latest issue has focused on the cross-device tracking which bring a serious threat 
to the privacy of users. A recent practice embeds ultrasonic beacons in audio device and tracks them using 
the microphone of mobile devices. Researchers have explored these new tracking technologies based on the 
capabilities, pervasiveness and technical limitations of existing commercial tracking solutions [37]—[39]. 
Figure | illustrate the development of ultrasonic technology and its application towards data exfiltration in 
computer security system. Some development and issues are the main concern of this paper which will be 
discussed further in later section. 
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Figure 1. The Development of Ultrasonic Technology and Its Applications towards 
Computer Security System 


3. SIGNAL LEAKAGE IN COMPUTER SYSTEM 
3.1. Data Exfiltration in Covert Channel 

The exfiltration of data from non-networked computers or those without physical access is still 
considered a challenging task. Among other type of computer security attack which exploit and exfiltrate data 
from air-gapped computers without requiring network connectivity is the covert channel. It started off as 
great debut in early year of 1980s and have been widely discussed in professional literature [40]—[42]. 
Different types of out-of-band covert channels have been proposed over the years, exploring the feasibility of 
data exfiltration through an air-gap. For example, the oldest kind of covert channel researched are likely to be 
the electromagnetic methods that exploit electromagnetic radiation from different components of the 
computer [43], [44]. 

Previously data exfiltration using audible and inaudible sound has been proposed and explored [45]-— 
[47]. Looking back over a decade, researchers proposed an ‘audio networking,’ which allows data 
transmission between a pair of desktop computers, using cheap speakers and a microphone [45]. The existing 
method shows that data can be transmitted through the air-gap via ultrasonic signal emitted from computer 
speakers. For instance, recent work in [46] suggest a method of transmitting keystroke data using a malware 
via ultrasonic audio emitted from computer speakers. The researchers proposed a method for near-ultrasonic 
in covert networking among air-gapped computers with a 20bit per second speed at a distance up to 19.7m 
using only speakers and microphones. They were able have a keylogger transmitting recorded keystrokes 
across a computers’ meshnet and collect the keystrokes of the primary victim computer on remote system. 
Another recent work has studied data leakage from a high-security of an air-gapped system to a low-security 
network systems using malware via high frequency signal within isolated internet environment [47]. The 
researchers demonstrated how the malware installed on the air-gap computer collected data, converted it into 
binary and then blinked LED accordingly. At the same time, the infected camera captured this pattern and the 
malware installed on the camera converted the Morse-code back into the binary data. These confirm the 
validity of the concern that ultrasonic data transmission between systems is a security threat. 

Data communication over inaudible sounds has been explored and extended for different 
environment using laptops and smartphones [48], [49]. High security organizations do employ controls that 
prevent radio signals from propagating into or out of the building. An interesting concept of transmitting data 
across solid metal mediums via ultrasonic transducers that would otherwise block radio signals able to 
achieve ultrasonic data transmission via Frequency-Shift Keying (FSK) with a bit rate of up to 800 bits per 
second [50]. However, it does not employ stock hardware that normal consumer electronics would use. 


3.2. Acoustic Cryptanalysis 

Side-channel attacks are a class of physical attacks in which an attacker tries to exploit physical 
information leakages from those devices. Side-channel attacks target implementations of cryptographic 
algorithms which can leak secret information through indirect channels such as power consumption, 
electromagnetic emanations, timing variations and acoustic emanations [51]-[54]. 

Acoustic attack is a type of side-channel attacks which mainly based on the sound produced by the 
devices especially computer peripherals or electrical components inside computers that may not be audible to 
human. Acoustic emanations that generated by computers, are one such potential channel. The source of 
attacks on the security of computer systems produced by emanations from electronic devices have long been 
investigated among researchers [12], [53], [55]—[57]. This attack is inexpensive and non-invasive because the 
only other hardware needed to perform the attacks is a parabolic microphone. Mechanical vibrations from 
fans and storage devices such as hard disks during system activity induced noise may carry valuable 
information that is apparently of little use for cryptanalysis. Physical intrusion into the system is also not 
required and the sound can be recorded from a substantial distance. It is crucial for public users and service 
providers to stay abreast of the progress and trends on cryptanalysis of security protocol. 
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In another perspective, recent work shows that ultrasonic signal has emanated from computers that 
emit a high-pitched signal during operation, due to vibration in some of their electronic components [58]. 
During the CPU operation, the power consumptions fluctuate to supply the constant voltage within the 
chipsets components. These acoustic emanations can expose and leak valuable information regarding 
security-related computations. The main issue was the very low acoustic side channel bandwidth that 
operates under 20 kHz using common microphones, and a few hundred kHz using ultrasound microphones. 
Interestingly, recent studies have shown that a full 4096-bit RSA key encryption can be extracted from a 
laptop computer by analysing the audible sound signal during operation [58], [59]. Data encryption standard 
RSA among the earliest practical public-key cryptosystems that is widely used for secure data transmission. 
The acoustic attacks are capable to extract the public keys from various versions of computers using the 
sound generated during the decryption of some chosen cipher texts. Figure 2 shows the overview of 
equipment that have been used in the experiment [58], [59]. Three experimental setups have been considered 
representing various trade-offs between costs, portability and measuring capabilities. This setup aims for the 
best possible acoustic acquisition quality (in terms of sensitivity, signal and frequency response) and high 
flexibility in measurement configuration. 
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Figure 2. An Illustration of Acoustic Attack on Mobile Computers in [58], [59] 


4. COUNTERMEASURES AND FURTHER PERSPECTIVES 

An obvious idea for counter measuring acoustic attacks is silent microprocessors, which do not 
produce any sound or leakage signal. The latest version of CPU for example like Intel i7 with quadcore 
processors and above would produce faster processing time and lower sound. Smaller size device such as 
tablets and mobile gadgets would also prevent the acoustic signals from transmitted externally. The above- 
mentioned ways are useful in avoiding emanation of sound from processors or CPUs. Other method is to 
increase the distance between the devices and the microphone in such a way where the signal detection rate 
drops substantially. Although this may not be useful to all cases as microphone technology for ultrasonic has 
developed rapidly in term of distance detection. Introduce some obstacles between the device and 
microphone can also prevent the sound reaching the recording device (microphone). Avoiding contact with 
microphone: the absence of microphones near emanation device is also sufficient to protect privacy. For 
acoustic attacks emanated from other component such as keyboard or printers, also required a silent and 
faster technologies. Nowadays, the usage of virtual technology replacing physical hardware may also among 
robust and state-of-the-art solutions. For example, virtual keyboards have appeared whereby they can be 
projected on a flat surface [60]—[62]. Similarly with recent project on the development of virtual microphone 
using ultrasonic signal as sound receiver although this method may require more devices as transceivers [63]. 
These choices are more expensive than the standard devices, yet it can avoid valuable information from 
leaking. 

Further work is currently being done to detect the leakage in private information caused by 
electronic devices’ emanations. The acoustic emanations originated from the operated microprocessors inside 
CPU of the attacked devices has been discussed based on computer operational running with RSA encryption 
protocol [58], [59]. The asymmetric properties of using two different keys makes the RSA become 
vulnerable as the cryptosystem itself is mainly based on the mathematical problem of integer factorization. 
AES, for instance, uses a unique key calculated few times based on several substitutions and linear 
transformation of the encryption key. AES algorithm remains the preferred encryption standard for high 
security system around the globe. Motivated by the significant finding on the signal leakage from RSA 
encryption, this current work is aimed to detect and characterizes signal profiles from the emanated ultrasonic 
signal running on AES encryption system and determine any correlation with respect to acoustic properties. 
Figure 3 shows the equipment used to perform the experiment using mobile computer running on AES 
encryption system. Ongoing measurement and analysis of these works are being carried out and anticipate 
with significant results for future publications. 
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Figure 3. Photograph of Author’s Portable Setup. In this Photograph (A) is a Target Computer, (B) is a 4” 
GRAS 46BF Microphone Set, (C) isa GRAS 12AK Microphone Power Supply and Amplifier, (D) is a 
National Instruments MyDAQ Device, and (E) is a Laptop Computer Performing the Attack 


5. CONCLUSIONS 

Exfiltration of data over ultrasonic signal in private information caused by inaudible sound signal 
emanated from electronic devices has been a wide concern recently. Audio device such as microphones and 
speakers can measure the sound signal as it carries sensitive information in the form of frequency, 
wavelength and amplitude. Powerful acoustic attacks in covert channel have been identified previously which 
mainly for capturing login detail, passwords and other secret information recovery. In cryptosystem, the 
acoustic emanations would be originated from computer peripherals or the operated microprocessors inside 
CPU of the attacked devices. Previous work has shown that the acoustic attack can convey information about 
the software running on the computer, and exfiltrate sensitive data about security-related computation. 
Ongoing work deals with the detection and profiling of the ultrasonic signal leakage emanated from a 
computer that runs AES-based encryption system. Interesting results from the current research are therefore 
anticipated to improve related computer security issues. 
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